Thirteen answers. Six things that stop being scary.
These are the controls a cyber insurer checks before writing a policy, and the ones small organizations actually get hit through. Get them right and the ordinary attacks bounce off. Here is what each one buys you.
A stolen password stops being a disaster.
With a second step at login, a leaked password gets an attacker nowhere. Without it, one password is your email, your bank, and your customers.
Known holes get closed while you sleep.
Most attacks use flaws fixed months ago. Machines that update themselves are not on that list.
Ransomware becomes a bad afternoon, not a closed business.
A backup you have actually restored from is the only backup that counts. An untested one is a guess.
The first hour of a bad day is spent acting, not deciding.
One page. Who calls whom. What gets unplugged first. That page is worth more than most software.
The next phishing email is a non-event.
Your people see more suspicious emails than any tool ever will. Twenty minutes a year changes what they click.
Somebody's name is on it.
If security is everybody's job, it is nobody's. One named owner is the cheapest control on the whole list.
What your insurer is actually asking
Context. A ten-person dental office and a sixty-person machine shop face different attackers and different rules. Your report reads differently for each, and so does an insurance application.
A stolen password is the front of most incidents. Multi-factor authentication turns a stolen password into a dead end. It is the first line on nearly every insurance application, and "available but optional" does not count with an underwriter.
An unpatched laptop is how known holes get used months after the fix shipped. Protection nobody monitors can be off for a year without anyone noticing. Insurers ask for both, and for someone watching.
A backup nobody tested is the difference between a bad week and a closed business when ransomware lands. A plan nobody wrote means the first hour of an incident is spent deciding who to call. Underwriters want a tested restore and a written plan.
Most incidents start with a person clicking something. And if security is everybody's job, it is nobody's. One named owner is the cheapest control on the list, and yearly training is on the application too.
In your own words. This is the part Blake reads first, because the thing keeping you up at night is usually the right place to start.
If you hold Department of Defense contracts, the same questions map to the basic practices in the CMMC program. The snapshot will not certify you, but it shows how far off the starting line you are before an assessor does.
